
CVE-2019-5420
Python exploit script for CVE-2019-5420, targeting Ruby on Rails signed-session AES GCM key brute-forcing to achieve remote code execution in…

Python exploit script for CVE-2019-5420, targeting Ruby on Rails signed-session AES GCM key brute-forcing to achieve remote code execution in…

Automated exploit for CVE-2025-59287, an unauthenticated RCE in WSUS, featuring payload generation, reverse shell listener, and AES encryption with…

Grafana Unauthorized arbitrary file reading vulnerability

Exploit for CVE-2019-18935 (Telerik UI) with WAF bypass via encrypted cookie payload injection and custom memory shell deployment.

Python toolkit for decrypting AES-256 and cracking PBKDF2 passwords from Grafana databases usually paired with (CVE-2021-43798)

Burp Suite/antsword - Interactive shell (HTTP hijack + POST + AES-256-CBC/BASE64)

BLE exploit framework for Unitree robots: command injection via hardcoded AES keys enables remote takeover, payload injection, and wormable…

[CVE-2020-1472] Netlogon Remote Protocol Call (MS-NRPC) Privilege Escalation (Zerologon)

An app with really insecure crypto. To be used to see/test/exploit weak cryptographic implementations as well as to learn a little bit more about…

Reproducible cryptanalysis artifacts for single-key recovery attacks on reduced-round AES, including black-box key recovery, DDT-Gray search, S-box…

Python implementation of a tool for decrypting and encrypting sensitive data in Grafana, specifically addressing the vulnerabilities associated with…

Exploitation toolkit for CVE-2025-59287 RCE in WSUS. Includes AES payload encryption and an exploitation module for authorized penetration testing.

Project Wycheproof tests crypto libraries against known attacks.

POC for CVE-2025-24132 (AirBourne). Currently just triggers the overflow and causes a crash